{"id":69012,"date":"2022-09-19T11:30:00","date_gmt":"2022-09-19T15:30:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=69012"},"modified":"2022-11-22T17:48:52","modified_gmt":"2022-11-22T22:48:52","slug":"identity-lifecycle-management-process","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/identity-lifecycle-management-process","title":{"rendered":"What Is the Identity Lifecycle Management Process?"},"content":{"rendered":"\n

The identity lifecycle management (ILM) process involves managing user identities and their access privileges from the beginning to the end of their involvement with your organization. <\/p>\n\n\n\n

This process begins on an employee\u2019s first day and continues throughout their employment, specifically when they change roles or need their access privileges altered. The process eventually ends once they have departed from your organization, all access has been revoked, and their digital identity is suspended, permanently revoked, or deleted entirely.<\/p>\n\n\n\n\n

\n
\n \"JumpCloud\"\n <\/div>\n
\n

\n <\/p>\n

\n Check out our webinar on practical tips for managing the user identity lifecycle. <\/p>\n <\/div>\n

\n Watch Webinar<\/a>\n <\/div>\n<\/div>\n\n\n\n\n

What Are the Phases of Identity Lifecycle Management?<\/h2>\n\n\n\n

The phases within the identity lifecycle management process are:<\/p>\n\n\n\n

  1. Identity creation.<\/li>
  2. Onboarding.<\/li>
  3. Monitoring, reporting, and maintenance.<\/li>
  4. Offboarding.<\/li><\/ol>\n\n\n\n
    \"chart<\/figure>\n\n\n\n

    1. Identity Creation<\/h3>\n\n\n\n

    The first step in managing the identity lifecycle is to create the digital identity that will be managed moving forward. Digital identity creation usually happens shortly before or on a new employee\u2019s first day. The first iteration of their digital identity is often created in HR\u2019s software which is commonly referred to as an HRIS tool.<\/p>\n\n\n\n

    HR gathers the relevant information from the new employee, uses it to create their digital identity, and associates a role or title to that identity. <\/p>\n\n\n\n

    2. Onboarding<\/h3>\n\n\n\n

    Once the new employee has an active digital identity in HR\u2019s software, it must also be created within IT\u2019s software. <\/p>\n\n\n\n

    Onboarding With Modern Tool Integrations<\/h4>\n\n\n\n

    The easiest, fastest, and most secure way to do this is through a built-in integration between the IT and HRIS tools<\/a> being used. In this scenario, the identity created in the HRIS tool is automatically imported into the IT software through the integration. <\/p>\n\n\n\n

    Once imported, the role associated with the identity in the HR software tells the IT tool what access needs to be provisioned. This is often done via groups<\/a> that have certain access to resources provisioned to them, so when a new identity becomes associated with a group, the proper access is immediately assigned.<\/p>\n\n\n\n

    Onboarding Without Modern Tool Integrations<\/h4>\n\n\n\n

    In all other scenarios without this useful integration, this phase of identity lifecycle management is much more difficult and time-consuming. In this case, HR and IT need to be in communication about when a user starts, what their role is, and what access they need. Then, come day one of their employment, HR and IT need to quickly create separate but mirrored identities in each tool. <\/p>\n\n\n\n

    After that, IT needs to manually provision access to each resource needed for that employee\u2019s role while also ensuring that the principle of least privilege access<\/a> is followed, but that enough access is provisioned for that employee to be productive right away. If multiple new employees are being welcomed on the same day, managing onboarding gets exponentially more difficult and tedious, significantly increasing the chances for human error to occur. <\/p>\n\n\n\n

    The consequences of this can be disastrous for productivity or security, depending on how little or how much access is wrongly provisioned.<\/p>\n\n\n\n

    Other Onboarding Management Tasks<\/h4>\n\n\n\n

    The other primary identity lifecycle management task that needs to happen during onboarding is email creation. The new employee\u2019s email address will be an important identifier moving forward, so it needs to follow the specific naming conventions that your organization adheres to. This email address will need to be set up in order for resource access to be granted appropriately.<\/p>\n\n\n\n

    While there are many other tasks that fall under the scope of onboarding<\/a>, those tasks are not specific to identity lifecycle management.<\/p>\n\n\n\n

    3. Monitoring, Reporting, and Maintenance<\/h3>\n\n\n\n

    The third phase of the identity lifecycle management process involves a few different but related tasks: <\/p>\n\n\n\n